The CBN circular requires payment transaction data to be stored and processed in Nigeria by January 1, 2027. NITDA has added a second condition. The infrastructure a bank moves to has to sit on a certified list.
That list is the Certified Cloud Register. It is scheduled to go live in October 2026. Banks, fintechs, and government institutions will be expected to source their cloud from providers on it. A provider that never gets certified means the migration happens twice.
This article is the procurement half of the data localisation problem. Articles One through Six covered what to move and how to design the architecture. This one covers who signs the contract.
What the Certified Cloud Register is
On 4 August 2026, NITDA signed three regulatory instruments under the National Sovereign Cloud Initiative: the National Cloud Computing Guideline, the National Cloud Technical Guideline, and the National Digital Infrastructure Assurance Framework (NDIAF), and presented the National Cloud Investment Strategy alongside them. The register is the operational piece of that package. Nairametrics, PRNigeria, CIO Africa and TechCabal reported the signing in August 2026.
Beginning October 2026, banks, fintechs, and government institutions are expected to source cloud from certified providers on the register. It covers cloud service providers, data centre operators, managed service providers, and AI infrastructure firms, with the same standards applied to indigenous providers and to hyperscalers. NITDA plans to operationalise a national digital regulatory platform by October 2026 for onboarding, assessment, certification and regulation, and the National Cloud Computing Guideline takes effect on 1 January 2027 (NITDA; CIO Africa, August 2026).
This register is not a side note. It is the supply side of the same deadline that Articles One through Six describe. The CBN says the data must be onshore by January 1, 2027. NITDA decides which onshore infrastructure counts. An institution can meet the CBN deadline and still be non-compliant if its provider is not on the register.
Why the register changes procurement
Most Nigerian institutions run their production estate on foreign public cloud. NITDA has cited that about 85% of Nigerian workloads sit on public cloud, most of it foreign-hosted (TechCabal, August 10, 2026). The register turns that default into a decision. Instead of asking which hyperscaler region to add, the question becomes which certified Nigerian provider to sign.
That is a bigger change than it sounds. A cloud provider is no longer a vendor that can be swapped. It is a compliance dependency. If a provider misses the register, gets certified late, or loses its certification, the institution's compliance posture moves with it. The architecture, the audit evidence, and the deadline all depend on a third party the institution does not control.
The register also covers government. The National Cloud Policy 2025 already classifies government data by sensitivity, with higher tiers required to sit on infrastructure that meets Nigerian certification and residency requirements. So this is not only a payments problem. It is the same procurement question for every agency that has to move off foreign cloud.
What certified is likely to mean
The full certification criteria for managed service providers have not been published as of mid-September 2026. UNVERIFIED. The register framework (NDIAF) is signed, but the specific checklist a provider must pass is not yet in the open.
What is public is the direction. NITDA's data classification in the National Cloud Policy 2025 puts Level 3 and Level 4 sovereign data exclusively in Nigeria. The register applies the same standards to indigenous and hyperscale providers. A local data centre does not get a pass just for being local. It has to meet the same assurance bar as a hyperscaler.
The practical read is this. A provider on the register will need to demonstrate data residency, security controls, and an auditable compliance posture. Certification is not a one-time event. It is a status that can be reviewed. When an institution signs a provider, it is betting on that provider's ability to keep the status through January and beyond.
The shortlist, and why a good data centre is not enough
The candidates are not secret. Here is the board as of mid-September 2026.
- Rack Centre. Lagos, Tier III, off-grid gas power.
- MDXi by Equinix. Lagos, Tier III, subsea cable landing.
- OADC. Lagos, expanding to about 24 MW.
- Kasi Cloud. Lagos, hyperscale-ready, targeting about 100 MW.
- Galaxy Backbone. Abuja and Kano, Tier III and Tier IV, PCI-DSS certified.
These are good facilities. That is not the question. The question is whether each one clears the register, and when. A data centre can be Tier IV and PCI-DSS certified and still miss the NITDA register if it does not complete the onboarding and assessment on time. Certification is a separate gate from physical quality.
There is a second gap worth naming. Kasi Cloud's CEO Johnson Agogbua made the point in an interview earlier this year: physical capacity is not the bottleneck. The missing layer is the cloud platform on top of the data centre. A bank migrating from AWS is not looking for a rack. It is looking for compute, storage, networking, and management tooling. The provider that wins is the one that offers the platform, not just the floor space. Article Two covers why infrastructure providers are ready but concentrated.
Questions to ask before signing
Here is the procurement checklist to run before signing any provider contract for a data localisation migration.
Ask whether the provider has applied for the register, and ask for evidence. Do not accept "we are working on it." A provider that has not started its NITDA onboarding in September is not going to be certified in October.
Ask what happens to the contract if the provider misses the register. This is the "fails softly" clause. A term of twelve months or less with a documented exit right keeps the institution out of a contract with a provider that failed its certification.
Ask about the second site. This is Article Five of the series. An onshore topology needs a primary and a DR site in different cities. A provider that only has Lagos capacity cannot solve the DR problem, no matter how good the Lagos facility is.
Ask for the power actuals. Lagos data centres bill on power with fuel surcharges that can move. Ask for twelve months of actual power and fuel billing before signing, and get the pricing model in the contract. This is the trap that turns a good colocation quote into a bad one.
Ask for compliance evidence export. The CBN does not just want the data onshore. It wants evidence. A provider that can hand over residency attestation, audit logs, and compliance reports is worth more than one that hands over a rack and a key card.
Ask for certification status in writing. If the provider cannot show its register application, its NDIAF assessment status, and a timeline, walk away. The register is the whole point.
The trap to avoid
The worst outcome in this migration is not a late cut-over. It is a multi-year contract with a provider that never gets certified, then a second move in 2027. That is two migrations, two sets of downtime, and a compliance gap in between.
The way to avoid it is to make certification a condition of the contract. Sign short. Verify before committing. Treat the register date, not the sales pitch, as the source of truth.
The position of this Journal
The series builds to this point. Article Three covers what to move. Article Four covers the control plane. Article Five covers the second site. Article Six covers the hybrid topology. This article covers the contract. Get the provider decision right and the rest of the plan has somewhere to land.
FIG. J7 — PROCUREMENT · CERTIFICATION AS A CONTRACT CONDITION · THE REGISTER IS THE GATE